xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Microsoft Windows Media Services NSIISlog.DLL远程缓冲区溢出漏洞


发布时间:2003-06-27
更新时间:2003-06-27
严重程度:
威胁程度:远程管理员权限
错误类型:边界检查错误
利用方式:服务器模式

BUGTRAQ ID:8035
CVE(CAN) ID:CAN-2003-0349

受影响系统
Microsoft Windows 2000 Advanced Server SP4  
Microsoft Windows 2000 Advanced Server SP3  
Microsoft Windows 2000 Advanced Server SP2  
Microsoft Windows 2000 Advanced Server SP1  
Microsoft Windows 2000 Advanced Server      
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server    
Microsoft Windows 2000 Server SP4            
Microsoft Windows 2000 Server SP3            
Microsoft Windows 2000 Server SP2            
Microsoft Windows 2000 Server SP1            
Microsoft Windows 2000 Server
未影响系统
Microsoft Windows NT Enterprise Server 4.0 SP6a          
Microsoft Windows NT Enterprise Server 4.0 SP6          
Microsoft Windows NT Enterprise Server 4.0 SP5          
Microsoft Windows NT Enterprise Server 4.0 SP4          
Microsoft Windows NT Enterprise Server 4.0 SP3          
Microsoft Windows NT Enterprise Server 4.0 SP2          
Microsoft Windows NT Enterprise Server 4.0 SP1          
Microsoft Windows NT Enterprise Server 4.0              
Microsoft Windows NT Server 4.0 SP6a                    
Microsoft Windows NT Server 4.0 SP6                      
Microsoft Windows NT Server 4.0 SP5                      
Microsoft Windows NT Server 4.0 SP4                      
Microsoft Windows NT Server 4.0 SP3                      
Microsoft Windows NT Server 4.0 SP2                      
Microsoft Windows NT Server 4.0 SP1                      
Microsoft Windows NT Server 4.0                          
Microsoft Windows NT Terminal Server 4.0 SP6a            
Microsoft Windows NT Terminal Server 4.0 SP6            
Microsoft Windows NT Terminal Server 4.0 SP5            
Microsoft Windows NT Terminal Server 4.0 SP4            
Microsoft Windows NT Terminal Server 4.0 SP3            
Microsoft Windows NT Terminal Server 4.0 SP2            
Microsoft Windows NT Terminal Server 4.0 SP1            
Microsoft Windows NT Terminal Server 4.0                
Microsoft Windows NT Workstation 4.0 SP6a                
Microsoft Windows NT Workstation 4.0 SP6                
Microsoft Windows NT Workstation 4.0 SP5                
Microsoft Windows NT Workstation 4.0 SP4                
Microsoft Windows NT Workstation 4.0 SP3                
Microsoft Windows NT Workstation 4.0 SP2                
Microsoft Windows NT Workstation 4.0 SP1                
Microsoft Windows NT Workstation 4.0                    
Microsoft Windows Server 2003 Datacenter Edition        
Microsoft Windows Server 2003 Datacenter Edition 64-bit  
Microsoft Windows Server 2003 Enterprise Edition        
Microsoft Windows Server 2003 Enterprise Edition 64-bit  
Microsoft Windows Server 2003 Standard Edition          
Microsoft Windows Server 2003 Web Edition                
Microsoft Windows XP Home SP1                            
Microsoft Windows XP Home                                
Microsoft Windows XP Media Center Edition                
Microsoft Windows XP Professional SP1                    
Microsoft Windows XP Professional
详细描述
Windows Media Services的日志记录ISAPI在处理客户端的请求时没有做充分的边界检查,远程攻击者可以利用此漏洞通过媒体服务在IIS的上下文中执行任意指令。

解决方案
厂商已经提供了补丁:

Microsoft Patch Q822343
http://microsoft.com/downloads/details.aspx?FamilyId=F772E131-BBC9-4B34-9E78-F71D9742FED8&displaylang=en

相关信息
Microsoft Security Bulletin MS03-022
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-022.asp